Skip to content

Merging Mental Models: Discovering Known Unknowns

In my career, I have had an unusual amount of success in finding interesting patterns that help me seemingly predict rough outlines of the future (think of it as Sounil's version of psychohistory). What I plan to share over the course of the next several weeks is my technique for seeing these patterns. Follow Knostic if you want to keep up with my latest ruminations.

The Cyber Defense Matrix is a model that I created to organize cybersecurity vendors and predict future capabilities we need in this field. However, it's not the future that I am predicting, but rather gaps in the present that point towards potential needs.

Mental models such as the Cyber Defense Matrix provide structure and help us find gaps to anticipate future needs. But they can also limit our thinking by keeping us within a proverbial box (or 25 boxes in the case with the Cyber Defense Matrix.)

There two ways to break out of this mental jail.

  1. One is to tweak the exist mental model. (I've gotten this suggestion many times now with the Cyber Defense Matrix. e.g., Can you add another column/row to represent Govern in the Cyber Defense Matrix?)
  2. But the other way to break out of the box is to look at an entirely different mental model and find conceptual linkages between the models.

In their book "Surfaces and Essences," Hofstadter and Sander suggest that Einstein's most advanced breakthroughs came from "an analogical leap that was analogous to another analogical leap." They further recount that Maxwell observed that he was attracted by parallels between parallels among different principles of physics. These additional layers of abstraction can be difficult to grasp at first, but the profundity that emerges is clear.

The implication here is that real breakthroughs emerge when you combine mental models, particularly across different domains. As an example, we have made meaningful progress in our understanding of cybersecurity through the merger of military-centric models such as the OODA loop and Kill Chain with cybersecurity.

This has inspired me to embark on a quest to discover deep linkages among mental models. I have made a few conceptual breakthroughs through the discovery of linkages among some cybersecurity-related mental models that most of us are already familiar with and I write with the hope that my readers can help find more. Who knows, maybe through this journey, we will discover cybersecurity's own grand unification theory.